Home  ›  Glossary  ›  Backup as a Service (BaaS)

What is backup as a service (BaaS)?

Backup as a service (BaaS) is backup delivered by a provider on subscription. The provider runs the backup software, storage and infrastructure, while the customer chooses what to protect and how long to keep it, paying per workload, per user or per terabyte stored. It follows the software-as-a-service model in the NIST definition of cloud computing.

Five ways providers deliver BaaS

For a small IT team, BaaS removes the backup server to patch, the repository to size and the offsite copy to arrange, and it puts a copy outside the building by default. For managed service providers it is a product line: one platform, operated once, sold to many customers. Offerings differ mainly in where the backups end up.

ModelWhere the backups live
Public cloud BaaSThe provider's cloud regions
SaaS application backupProvider storage, read through the APIs of platforms such as Microsoft 365
MSP-hostedThe MSP's data center, running commercial backup software
HybridA local appliance for fast restores, replicated to provider storage
Internal BaaSA central IT platform offered to business units as tenants

Seeding the first full and pulling back the last

Everything a BaaS customer protects travels over the same link in both directions. A first full backup of 20 TB over 1 Gb/s takes close to two days of continuous transfer (20 × 8,000 = 160,000 seconds), after which only changed data moves. Providers often seed large tenants by shipping a disk appliance and importing it at the data center.

Restores are where the link really bites. A single deleted file comes back in seconds. A site-wide ransomware recovery of 30 TB at 1 Gb/s needs at least 240,000 seconds, close to three days, before protocol overhead, and at 10 Gb/s it falls to under seven hours. That gap explains why hybrid designs keep a local copy and why providers offer to run recovered workloads in their own compute or ship data back on physical devices. Read speed on the provider side is covered under restore throughput.

Tenant logins and the provider console

A customer's portal login is effectively a key to its backups. When an attacker steals the tenant administrator's credentials, the deciding detail is whether that account can delete backups or shorten retention. Retention enforced by the provider's storage, beyond the reach of any tenant account, keeps the backups through the stolen login. Retention that is only a portal setting goes with it.

The MSP's own admin accounts and tools reach every tenant, so a single compromise in the provider's management plane threatens all customers at once. The separation that holds in that case sits beneath the backup software: tenant identities, buckets and retention locks that stay in force while the MSP console is in the wrong hands, the model described under multi-tenancy.

Per-terabyte pricing and the country the data sits in

Where the provider stores backups decides which jurisdiction's rules apply, a question covered under data residency and data sovereignty. Pricing per stored terabyte turns long retention and lock periods into a visible monthly cost. Pricing per workload or per user folds them into plan limits that surface only when exceeded.

ARTESCA and backup as a service

Service providers use ARTESCA as the storage layer beneath BaaS offerings. Its IAM-style access model gives each tenant separate accounts, keys and buckets, so a tenant login reaches only that tenant's data, and S3 Object Lock in governance or compliance mode can be set per tenant bucket. Maestro manages fleets of multiple ARTESCA clusters.

With compliance mode on a tenant bucket, neither the tenant's portal login nor the provider's own administrators can shorten retention before the retain-until date. For Microsoft 365 backup services, ARTESCA is validated with Veeam Backup for Microsoft 365. Link speed for seeding and large restores is a limit the storage does not change.